{"id":"GHSA-7fpj-wc8v-9cgc","summary":"Duplicate Advisory: terminal42/contao-tablelookupwizard possible SQL injection in widget field value","details":"## Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-v3mr-gp7j-pw5w. This link is maintained to preserve external references.\n\n## Original Description\n## Impact\nThe currently selected widget values were not correctly sanitized before passing it to the database, leading to an SQL injection possibility.\n\n## Patches\nThe issue has been patched in tablelookupwizard version 3.3.5 and version 4.0.0.\n\n## For more information\nIf you have any questions or comments about this advisory:\n\n- Open an issue in https://github.com/terminal42/contao-tablelookupwizard\n- Email us at info@terminal42.ch","modified":"2026-02-03T03:07:40.767259Z","published":"2024-05-30T13:12:13Z","withdrawn":"2026-01-23T22:53:11Z","database_specific":{"github_reviewed_at":"2024-05-30T13:12:13Z","nvd_published_at":null,"cwe_ids":["CWE-89"],"severity":"CRITICAL","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/terminal42/contao-tablelookupwizard/security/advisories/GHSA-v3mr-gp7j-pw5w"},{"type":"WEB","url":"https://github.com/terminal42/contao-tablelookupwizard/commit/a5e723a28f110b7df8ffc4175cef9b061d3cc717"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/terminal42/contao-tablelookupwizard/2022-02-04-1.yaml"},{"type":"PACKAGE","url":"https://github.com/terminal42/contao-tablelookupwizard"}],"affected":[{"package":{"name":"terminal42/contao-tablelookupwizard","ecosystem":"Packagist","purl":"pkg:composer/terminal42/contao-tablelookupwizard"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.0.0"},{"fixed":"3.3.5"}]}],"versions":["2.0.1","3.0.0","3.1.0","3.1.1","3.1.2","3.1.3","3.2.0","3.2.1","3.3.0","3.3.1","3.3.2","3.3.3","3.3.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-7fpj-wc8v-9cgc/GHSA-7fpj-wc8v-9cgc.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}